Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeHoopla Extension
Findings · 3
+1 more finding locked
HIGH FINDINGS · 3
  1. 01Background fetches a remote 'CAA' (Coupon-Apply-At-checkout) ruleset from a third-party vendor (besttoolbars) and from hoopladoopla.com, then ships the entire ruleset into the <all_urls> content script which uses server-supplied CSS selectors and HTTP request templates (URL/method/body/headers) to read and modify form fields and to issue XHR/fetch from page origin context.
  2. 02Sends checkout-page telemetry (cart total, savings, store name+id, coupon code attempted, page hostname, extension id+version) to a third-party analytics endpoint at analytics.besttoolbars.net when the user has consented to analytics.
  3. 03Background uses chrome.webNavigation.onBeforeNavigate and chrome.tabs.onUpdated to inspect every URL the user visits and match it against a hard-coded list of 30+ affiliate-network domains (CJ, Rakuten, Awin, eBay, doubleclick affiliate-click trackers, etc.); per-tab affiliate-flow state is then persisted in chrome.storage.local and used to drive cashback prompts.
+1 more finding locked
OTHER EXTENSIONS

Is Hoopla Extension safe?

High risk

No summary available.

Hoopla Dooplav1.0.30Chrome Web Store
75Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+1 more finding not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026com.hoopladoopla.extension.safari.extension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact